PT-2026-33823 · Openclaw · Openclaw

Zou Dikai

·

Published

2026-04-17

·

Updated

2026-04-21

·

CVE-2026-41389

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.4.7 through 2026.4.14
Description Failure to enforce local-root containment on tool-result media paths allows arbitrary local and UNC (Universal Naming Convention, a standard for specifying network shares) file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosing sensitive files or exposing credentials.
Recommendations Update to version 2026.4.15.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41389
GHSA-MR34-9552-QR95
GHSA-QC5J-2MQX-X83Q

Affected Products

Openclaw